The normative requirements of the AI-Native Medical specification, stated as numbered RFC 2119 clauses, with three conformance classes an implementation may claim against.
Clauses
79
Absolute
70
Recommended
8
Optional
1
Chapters
10
Interpretation of requirement levels
The key words below are to be interpreted as described in IETF RFC 2119. They appear in capitals wherever they carry normative force, and only there.
MUST
An absolute requirement. A deployment that does not satisfy a MUST clause applicable to its claimed conformance class does not conform to this specification.
MUST NOT
An absolute prohibition. The named capability, path, or practice is required to be absent — not merely disabled by configuration or forbidden by policy.
SHOULD
A strong recommendation. Valid reasons may exist to deviate in particular circumstances, but the full implications must be understood and the deviation documented.
SHOULD NOT
A strong discouragement. The behavior is permitted only where its consequences have been examined and accepted in writing.
MAY
Truly optional. An implementation that omits a MAY clause remains fully conformant, and one that includes it must interoperate with one that does not.
Conformance classes
A conformance claim is meaningless unless it is scoped. Each class below is a distinct, mutually exclusive claim about what a deployment actually does — and, just as importantly, what it does not.
Class A — Sovereign Ambient Enclave
72 applicable · 64 absolute
The complete architecture. Tenant-owned inference hardware inside an acoustically engineered enclave, with continuous ambient ingestion, physical identity enforcement, and no egress path for inference payloads.
Applicability
Claimed by deployments serving regulated practice areas where the spoken record is the primary asset: transaction teams, litigation groups, clinical review, and investment committees.
What the claim excludes
A Class A claim requires every clause in this specification marked applicable to Class A, including the full acoustic and ambient-ingestion requirements. Partial ambient capability is a Class B deployment, not a reduced Class A.
Class B — Sovereign Compute Enclave
61 applicable · 55 absolute
Tenant-owned inference hardware inside a declared demarcation boundary with no egress path, but without continuous ambient sensory ingestion. Input arrives through conventional interfaces.
Applicability
Claimed by organizations that require sovereign inference and zero egress but are not prepared to operate continuous ambient capture, whether for works-council, jurisdictional, or cultural reasons.
What the claim excludes
A Class B deployment makes no ambient-intelligence claim and must not be described as capturing the spoken record. Acoustic clauses apply only insofar as they protect displayed and audible material.
Class C — AI-Ready Shell
18 applicable · 18 absolute
Building infrastructure prepared to host a Class A or Class B enclave — power, cooling, structural, and pathway capacity verified — with no tenant compute installed and no inference occurring.
Applicability
Claimed by property owners and developers documenting readiness in advance of a tenant. Class C is a property-layer claim about capability, not an operational claim about workloads.
What the claim excludes
A Class C claim conveys nothing about data handling, because no data is processed. Class C must never be represented as sovereign inference, and a Class C shell must not be marketed as an AI-Native Medical in operation.
1Conformance & Terminology
How a claim of conformance is made, scoped, and withdrawn. These clauses govern the use of the specification itself rather than the architecture it describes.
An implementation claiming conformance to the AI-Native Medical specification MUST declare exactly one conformance class — A, B, or C — together with the specification version against which the claim is made.
Rationale (non-normative)
An undifferentiated claim of conformance is unfalsifiable. Naming a class and a version makes the claim reviewable and lets it expire honestly as the specification advances.
Verification
The claim is published in writing and names both the class and the version.
A conformance claim MUST identify the specific physical premises to which it applies, and MUST NOT be stated at the level of an organization, a product, or a portfolio.
Rationale (non-normative)
Conformance in this specification is a property of a room and the hardware inside it. An organization-wide claim would assert something the architecture cannot guarantee across sites.
An implementation MUST NOT describe a conformance claim as certification, accreditation, or independent review unless an independent conformance body has been established and has issued that finding.
Rationale (non-normative)
No such body exists at the time of this revision. All current claims are self-declared, and representing them otherwise would misstate their weight.
A deployment that ceases to satisfy any MUST clause applicable to its declared class MUST withdraw or downgrade its conformance claim before continuing to represent itself as conformant.
Rationale (non-normative)
Conformance describes an operating condition, not a milestone once achieved. Hardware is removed, boundaries are redrawn, and claims must track those changes.
2The Demarcation Boundary
Every other requirement in this specification is evaluated against a boundary. These clauses require that the boundary be declared explicitly, enumerated exhaustively, and kept inspectable.
A conforming deployment MUST declare a demarcation boundary that is simultaneously physical and logical, identifying the rooms, racks, and network segments inside which tenant data is processed.
Rationale (non-normative)
A boundary that exists only as a network diagram cannot support a claim grounded in physical custody. The declaration must be walkable.
Verification
A written boundary declaration exists and can be reconciled against a site plan.
A conforming deployment MUST maintain a current and exhaustive enumeration of every network path that crosses its demarcation boundary, including management, telemetry, licensing, update, and out-of-band paths.
Rationale (non-normative)
Egress claims fail at the paths nobody counted. Management and telemetry channels are the usual omissions, and both are capable of carrying payload.
Verification
The enumeration is complete against an independent scan of the boundary and is dated within the current review period.
Each boundary-crossing path enumerated under ANM-2.2 MUST be annotated with the categories of data it is capable of carrying, and MUST be justified against the deployment's operating requirements.
A conforming deployment SHOULD be able to continue serving inference for a defined minimum interval with all boundary-crossing paths severed, and SHOULD document that interval.
Rationale (non-normative)
Survivability under full disconnection is the practical test of sovereignty. A deployment that halts when the uplink drops was never independent of it.
A Class C shell MUST declare the boundary a future enclave is intended to occupy, and MUST state plainly that no demarcation boundary is presently in force because no tenant compute is installed.
3Data Movement & Egress
The zero-egress property, stated as a prohibition on paths rather than a preference for behavior. A control that could be reconfigured to permit egress does not satisfy this chapter.
A conforming deployment MUST NOT transmit inference payloads — prompts, retrieved context, intermediate representations, embeddings, or generated outputs — across its demarcation boundary during normal operation.
Rationale (non-normative)
This is the specification's central prohibition. Embeddings and intermediate representations are named explicitly because they are frequently treated as non-sensitive despite being derived directly from privileged material.
Verification
Egress monitoring over a representative operating period shows no payload-bearing flow across any enumerated path.
The absence of an egress path for inference payloads MUST be a structural property of a conforming deployment rather than a policy, feature flag, or configuration setting that a privileged operator could reverse.
Rationale (non-normative)
A prohibition that can be lifted by changing a setting is a procedural control wearing structural language, and it collapses under the examination this architecture is meant to withstand.
A conforming deployment MUST NOT send tenant-derived telemetry, usage analytics, error payloads, or diagnostic samples to any party outside its demarcation boundary.
Rationale (non-normative)
Diagnostic exhaust is the most common unexamined egress channel, and stack traces and error payloads routinely contain the exact material the boundary exists to hold.
A conforming deployment MAY transmit aggregate operational counters that contain no tenant-derived content, provided each such counter is enumerated under ANM-2.2 and disclosed to the tenant.
Rationale (non-normative)
Sovereignty need not preclude knowing whether a fan is failing. The requirement is that the exception be named rather than assumed.
Model weights, container images, and software updates entering a conforming deployment MUST be verified against a cryptographic signature before installation, and the verification MUST be performed inside the demarcation boundary.
Rationale (non-normative)
Inbound supply chain is the boundary's remaining exposure once egress is closed. Verifying outside the boundary reintroduces the trust dependency.
A conforming deployment SHOULD NOT depend on an external service for any function on the critical path of inference, including authentication, license validation, model retrieval, or rate authorization.
A conforming deployment MUST implement the administrative, physical, and technical safeguards required by 45 CFR §§ 164.308 and 164.312 within the demarcation boundary, and MUST NOT rely on the absence of an egress path as a substitute for them. At minimum this includes unique user identification with role-based access control, encryption of Protected Health Information at rest, mutually authenticated encryption in transit across intra-enclave hops, append-only audit logging, integrity verification of stored artifacts and model weights, a hardware root of trust with measured boot, and a documented risk analysis naming the enclave in scope.
Rationale (non-normative)
Zero egress is one physical and technical control inside a defense-in-depth architecture. The Security Rule applies in full to hardware sited within the practice's own walls, and a local deployment that neglects access control, encryption, or audit logging is no more defensible than a cloud one.
Verification
Evidence for each enumerated safeguard, together with a current risk analysis whose scope statement names the enclave.
An implementation MUST NOT represent zero-egress architecture, on-premises siting, or tenant hardware ownership as establishing HIPAA compliance, and MUST NOT describe compliance as an architectural property of the real estate.
Rationale (non-normative)
Compliance is a program obligation assessed against a covered entity's safeguards, not a conclusion derivable from network topology. Presenting architecture as compliance invites a reviewer to substitute a siting decision for a risk analysis.
An implementation claiming reduced Business Associate Agreement exposure MUST scope that claim to the elimination of third-party hyperscaler data processors and their subprocessor chains, and MUST maintain Business Associate Agreements with every party that creates, receives, maintains, or transmits Protected Health Information on the covered entity's behalf, including managed-service providers, integrators holding privileged access, local software vendors with support access, and property personnel whose maintenance role reaches systems processing Protected Health Information.
Rationale (non-normative)
Locality removes a category of business associate; it does not remove the category. The defensible claim is a small, locally situated, individually auditable set of agreements rather than their absence.
Verification
A current business-associate register with executed agreements, reconciled against every party holding privileged access to the enclave.
A conforming deployment MUST distinguish minimization of raw ambient capture from retention of generated artifacts, and MUST treat clinical documentation, finalized reports, triage outputs, structured observations, and audit records as persistent Protected Health Information subject to ANM-3.7, the tenant's retention schedule, and applicable breach-notification obligations. An implementation MUST NOT claim that no persistent Protected Health Information exists.
Rationale (non-normative)
The system's outputs are the purpose of the system, and they persist. Releasing a volatile capture buffer minimizes raw media exposure; it is not a cryptographic erasure proof, and it says nothing about the records written downstream.
Verification
A documented artifact lifecycle identifying each persisted class, its storage location inside the boundary, its encryption state, and its retention period.
Where inference executes, on whose hardware, and under what failure and dependency conditions. These clauses establish that sovereignty is a property of physical custody.
The tenant MUST hold outright ownership of the accelerator hardware, the storage media, the inference data, and all model outputs produced within a conforming deployment.
Rationale (non-normative)
Ownership rather than lease or license is what makes the tenant's custody claim survive the insolvency, acquisition, or policy change of any counterparty.
A conforming deployment MUST NOT route any portion of an inference request to a model endpoint hosted outside its demarcation boundary, including for overflow capacity, fallback, quality comparison, or evaluation.
Rationale (non-normative)
Hybrid routing defeats the entire architecture while preserving its vocabulary. A single fallback path to a hosted endpoint makes every prior guarantee conditional.
A conforming deployment MUST be provisioned with power and thermal capacity sufficient to sustain its accelerator hardware at continuous full utilization rather than at intermittent or bursty load.
Rationale (non-normative)
Ambient and agentic workloads are continuous by nature. Sizing to office-equipment duty cycles produces thermal throttling that is then misdiagnosed as a model limitation.
A conforming deployment MUST provide backup power sufficient to bring inference hardware and storage to an orderly shutdown without loss of tenant data.
Inference hardware in a conforming deployment SHOULD be sited to keep end-to-end response latency dominated by computation rather than by network transit.
Rationale (non-normative)
The architecture's experiential claim is that machine capability feels adjacent. Latency budget spent on transit is the one cost this siting exists to eliminate.
A Class C shell MUST document its available power capacity, thermal rejection capacity, floor loading, and cable pathway capacity in terms that permit a prospective tenant to size an enclave against them.
A deployment claiming an interactive latency figure MUST publish a glass-to-photon latency budget that allocates the end-to-end path across sensor capture, local transport, inference execution, and render and scan-out, and MUST state the measured contribution of each stage rather than the inference time alone.
Rationale (non-normative)
GPU proximity removes wide-area transit from the path and nothing else. Sensor integration, codec conversion, scheduling jitter, and display scan-out routinely exceed the inference kernel, so a figure derived from locality alone is not a claim about what a clinician perceives.
Verification
A published budget table whose stage allocations sum to the claimed total, each traceable to an instrumented measurement method.
Latency claims supporting augmented-reality or other interactive clinical guidance MUST be measured end to end at the display surface under representative clinical load, and MUST be reported at the 99th percentile rather than as a mean or best-case value.
Rationale (non-normative)
Procedural error is induced by the slow frames, not the average one. A mean figure captured on an idle node conceals exactly the tail behavior that determines whether an overlay is safe to rely on during instrument manipulation.
Verification
Measurement records showing p99 end-to-end latency with concurrent inference workloads active, captured at the panel rather than at kernel exit.
An implementation MUST NOT characterize inference latency as sub-millisecond, instantaneous, or real-time when describing an end-to-end interactive path that includes sensor capture and display rendering.
Rationale (non-normative)
Sub-millisecond figures describe individual operations such as an in-memory graph traversal. Applying them to a perceptual path that necessarily includes capture and scan-out overstates the system's behavior by an order of magnitude.
5The Acoustic Enclave
Physical containment of the captured field. Continuous ambient capture is defensible only where the room can be shown to contain what it hears, which makes acoustics a security control.
An enclave in a Class A deployment MUST achieve a Sound Transmission Class rating of not less than STC 55 across every partition, door, and penetration bounding the captured acoustic field.
Rationale (non-normative)
STC 55 is a laboratory assembly rating adopted here as a construction floor, not a statement about speech intelligibility in the delivered room. Stating a number converts confidentiality from an assertion into an inspectable building property; ANM-5.7 states the field criterion the number is intended to achieve.
Verification
Field testing of the assembled construction, not the rated assembly specification alone.
Acoustic performance in a Class A deployment MUST be verified by field measurement of the constructed enclave after installation of all services, and MUST NOT be claimed solely on the basis of laboratory ratings for the specified assemblies.
Rationale (non-normative)
Rated assemblies routinely underperform once penetrated by conduit, ductwork, and outlets. The delivered room is the only meaningful subject of the measurement.
Every mechanical, electrical, and plumbing penetration of a Class A enclave boundary MUST be acoustically sealed and MUST be included in the verification required by ANM-5.2.
A Class A enclave MUST maintain an ambient noise floor low enough for reliable speech capture at the far field of the room, so that ingestion accuracy does not depend on participants addressing a device directly.
Rationale (non-normative)
Ambient intelligence fails quietly when the room is noisy: the system degrades to capturing only the loudest speaker, which is rarely the most consequential one.
A Class B deployment SHOULD apply the acoustic requirements of this chapter to any space in which privileged material is displayed or discussed, notwithstanding the absence of ambient capture.
A Class C shell claiming acoustic readiness MUST identify which specific spaces are capable of achieving STC 55 and what construction is outstanding, and MUST NOT represent an unbuilt rating as achieved.
A Class A enclave MUST demonstrate confidential speech privacy in the constructed room by achieving a Privacy Index greater than 95% and an Articulation Index below 0.05, measured under ASTM E1130 field testing conditions.
Rationale (non-normative)
Sound Transmission Class rates an assembly in a laboratory; it does not measure the intelligibility of speech leaving a finished room with doors, returns, and flanking paths. Privacy Index and Articulation Index are the recognized field metrics for confidential speech privacy, which makes them the correct basis for a security claim.
Verification
An ASTM E1130 field measurement report for each enclave, produced after all services are installed, stating measured PI and AI values against the source and receiver positions used.
An implementation MUST NOT represent any Sound Transmission Class rating as rendering speech inaudible, unrecoverable, or immune to reconstruction, and MUST NOT describe an acoustic assembly as an air gap.
Rationale (non-normative)
Acoustic isolation reduces intelligibility to a measurable threshold under defined test conditions. It does not defeat an instrumented adversary using structural or vibration-based capture, and stating otherwise misrepresents the control to reviewers who may rely on it.
How ambient reality enters the system, and what the ingestion layer is forbidden to retain. Statelessness is required here precisely because raw capture is the largest available liability.
The ingestion layer of a Class A deployment MUST NOT persist raw uncompressed acoustic or spatial capture to durable storage at any point in its processing pipeline.
Rationale (non-normative)
A durable archive of everything ever said in an institution is an extraordinary liability and an unnecessary one, because the structured product of the capture is what carries the value.
Verification
Storage inspection during and after an active capture session shows no raw retention.
The ingestion layer of a Class A deployment MUST reduce ambient capture to structured records in flight, and MUST discard the source capture once reduction completes.
A Class A deployment MUST make the operating state of ambient capture perceptible to every person present in the enclave without requiring that person to consult a screen or an application.
Rationale (non-normative)
Consent to ambient capture is meaningless if its subjects cannot tell whether it is active. The indication belongs to the room, not to a settings panel.
A Class A deployment MUST provide an in-room means of suspending ambient capture that is available to any occupant and that takes effect without administrative approval.
Structured records derived from ambient capture MUST remain inside the demarcation boundary and MUST inherit every prohibition of Chapter 3 that applies to inference payloads.
Rationale (non-normative)
Derived records are frequently treated as a different class of data than the capture they came from. They are not, and the boundary must not distinguish them.
A Class A deployment SHOULD support per-session exclusion of identified participants from ambient capture, so that privilege, works-council obligations, and individual objection can be honored without disabling the room.
The bounds within which autonomous software may act. These clauses constrain tool invocation, including invocation through the Model Context Protocol, to authority that is physically established.
The orchestration layer of a conforming deployment MUST execute inside the demarcation boundary, including its policy evaluation, routing decisions, and scheduling state.
Rationale (non-normative)
An orchestrator hosted outside the boundary observes every request it routes, which reproduces the exposure the boundary was drawn to prevent.
Every tool invocation available to an autonomous agent in a conforming deployment MUST be declared in advance, and an agent MUST NOT acquire a capability at runtime that was not present in its declared set.
Rationale (non-normative)
Dynamic capability acquisition makes an agent's authority unbounded and unauditable, which no regulated institution can grant standing access under.
Tool invocation through the Model Context Protocol in a conforming deployment MUST be authorized against the physical identity established under Chapter 8, and MUST be denied when no authorizing presence is established.
Rationale (non-normative)
This is the specific point at which the agentic workload meets the physical architecture: an agent's reach is bounded by who is verifiably in the room, not by a credential that may have leaked.
A conforming deployment MUST record every autonomous tool invocation with the invoking agent, the authorizing identity, the parameters supplied, and the outcome, and MUST retain that record inside the demarcation boundary.
A conforming deployment MUST classify tool invocations that mutate external state, transfer value, or communicate outside the organization as requiring explicit human authorization for each occurrence.
Rationale (non-normative)
Autonomy is acceptable for reasoning and retrieval and unacceptable for irreversible action. The line is drawn at consequence, not at capability.
Retrieval assets built from tenant material — indexes, knowledge graphs, embeddings, and evaluation sets — MUST be stored inside the demarcation boundary and MUST be owned by the tenant.
A conforming deployment SHOULD express retrieval over typed relationships between people, documents, decisions, and events rather than over undifferentiated similarity alone.
Rationale (non-normative)
The ambient record's distinctive value is relational: who met whom, about what, and in what order. Flat similarity search discards precisely that structure.
A conforming deployment MUST interpose a policy and authorization engine between the agent and the Model Context Protocol server, such that no tool invocation reaches building hardware or clinical records on the model's authority alone. Policy MUST be externalized from both the model weights and the Model Context Protocol server, MUST be evaluated deterministically, and MUST default to deny.
Rationale (non-normative)
A model that ingests ambient clinical dialogue is ingesting untrusted input. Placing the authorization decision outside the model is what prevents a phrase spoken in the room, dictated from a patient's document, or embedded in a scanned referral from redirecting the agent, and it keeps the decision reviewable by an examiner.
Verification
Configuration evidence showing an external decision engine in the invocation path, its policy corpus under version control, and a default-deny result for an undeclared tool.
A conforming deployment MUST treat all ambient capture, patient-supplied documents, and third-party correspondence entering the inference path as untrusted input with respect to agent authority, and MUST NOT allow instructions originating in that content to alter the agent's declared tool set, its authorization scope, or the policy governing it.
Rationale (non-normative)
Prompt injection, privilege escalation through chained invocations, and confused-deputy execution against door-strike or record-retrieval interfaces are the governing risks of an agentic clinical deployment. None of them are mitigated by processing the model locally.
Verification
Documented adversarial testing against injection and escalation attempts, with results retained inside the boundary.
Transport between the agent, the policy and authorization engine, and the Model Context Protocol server MUST be mutually authenticated using short-lived workload credentials, and authorization MUST be expressed as fine-grained access control enumerated per tool rather than as a single privileged service identity.
Rationale (non-normative)
The local network sits inside the demarcation boundary but not inside the trust boundary. Locality is not a substitute for authenticating the workloads that speak to each other across it.
Verification
Certificate and policy configuration showing mutual authentication on each hop and a per-tool authorization matrix.
An implementation MUST NOT treat a discovery artifact such as an llm.txt file as a source of authority, capability, or policy. Machine-level execution MUST be carried by the Model Context Protocol and local programmatic endpoints, and a conforming deployment MUST operate fully with no discovery artifact present.
Rationale (non-normative)
A discovery file is a documentation convention that is trivially editable and unauthenticated. Elevating it to a system-level protocol would place the enclave's capability model in a file that confers no cryptographic assurance whatsoever.
Entry to the enclave is an authentication event. These clauses require that physical presence be established, recorded, and bound to the inference sessions it authorizes.
A conforming deployment MUST treat entry to the enclave as an authentication event of equal standing to a software credential, and MUST record it as such.
Rationale (non-normative)
A sovereign compute environment is only as strong as its physical access log. Treating the door as facilities management rather than as identity infrastructure leaves the strongest control unrecorded.
A conforming deployment MUST bind each inference session to the physical identity or identities established as present in the enclave at the time the session is initiated.
Physical access records for a conforming deployment MUST be retained inside the demarcation boundary and MUST be subject to the prohibitions of Chapter 3.
Rationale (non-normative)
Access logs describe who was in the room and when, which is itself privileged information in a transaction, litigation, or clinical context.
A conforming deployment MUST NOT permit administrative access to inference hardware, storage, or orchestration state from outside its demarcation boundary.
Rationale (non-normative)
Remote administrative access is a payload-capable path with the highest privilege in the system, and its convenience is the most common reason sovereignty claims fail on inspection.
Maintenance performed by a software integrator MUST occur under an identity distinct from any tenant identity, and MUST be recorded with the same fidelity required of tenant access by ANM-8.1.
A Class C shell MUST document the physical access control provisions available at the intended enclave location, and MUST NOT claim identity binding, because no inference sessions exist to bind.
9Ownership & Governance
The Tripartite Ownership Model, stated as enforceable separations rather than as commercial preference. These clauses define what each party is forbidden to hold.
A conforming deployment MUST separate the property owner, the tenant, and the software integrator into distinct parties whose holdings do not overlap, in accordance with the Tripartite Ownership Model.
Verification
Executed agreements reflect the separation and are available for examination.
The property owner in a conforming deployment MUST NOT hold ownership of, access to, or a contingent interest in tenant compute hardware, inference data, retrieval assets, or model outputs.
Rationale (non-normative)
This separation is what allows a landlord to finance and install sovereign infrastructure without acquiring rights that would make the tenant's custody claim unsustainable.
The software integrator in a conforming deployment MUST NOT hold ownership of tenant data, policies, evaluations, routing logic, retrieval assets, or commissioned model adaptations.
A conforming deployment MUST provide the tenant with a documented exit under which inference capability, retrieval assets, and accumulated institutional memory remain operable after termination of any agreement with the software integrator or the property owner.
Rationale (non-normative)
Sovereignty that evaporates at contract termination was vendor dependence with a longer notice period.
A conforming deployment MUST disclose to the tenant every third-party license, model license, and usage restriction that constrains the tenant's use of outputs produced within the enclave.
A conforming deployment MUST NOT use tenant material to train, fine-tune, evaluate, or improve any model or system made available to another party.
Rationale (non-normative)
Cross-tenant improvement is the mechanism by which a sovereignty claim is most often quietly voided, and it is rarely visible in the operating architecture.
A Class C shell MUST disclose the ownership structure under which a future enclave would be delivered, so that a prospective tenant can evaluate the separation required by ANM-9.1 before committing.
Where the property owner is or may be a referral source for the tenant, space and compute arrangements between the parties MUST satisfy an applicable rental exception under 42 CFR § 411.357 in full, including a signed written agreement, a term of at least one year, a description of the premises and equipment covered, space and equipment not exceeding what is reasonable and necessary for the tenant's legitimate business purposes, compensation set in advance at fair market value, and commercial reasonableness assessed independent of referrals.
Rationale (non-normative)
Fair market value is a necessary condition of a defensible arrangement, not a safe harbor in itself. The rental exceptions impose several further conditions, and an arrangement priced correctly but structured loosely still fails.
Verification
Executed agreements together with a contemporaneous independent valuation, refreshed on a defined cycle rather than performed once at signing.
Compute pricing, capacity allocation, tiering, escalation, discounts, and service credits MUST NOT be determined in any manner that takes into account the volume or value of referrals or other business generated between the parties. Percentage-of-revenue and per-referral compute pricing MUST NOT be used.
Rationale (non-normative)
Capacity provisioned by reference to a tenant's referral footprint rather than its clinical throughput is the specific failure mode this architecture could otherwise enable at scale, and the Anti-Kickback Statute turns on intent rather than on valuation mechanics.
Verification
The compute rate schedule and allocation methodology, documented in terms of throughput and capacity units with no referral-derived variable.
What a deployment must be able to show an examiner. The specification's compliance argument is structural, which obligates it to be demonstrable on inspection.
A conforming deployment MUST be able to demonstrate the absence of an egress path for inference payloads to an examiner on site, without relying on an attestation issued by a third party.
Rationale (non-normative)
The specification's compliance argument is that architecture can be shown rather than asserted. That claim obligates the deployment to be demonstrable on inspection.
A conforming deployment MUST maintain records of physical access, tool invocation, model and software version history, and boundary configuration changes, sufficient to reconstruct the operating state of the enclave at any past point within its retention period.
A conforming deployment MUST identify the specific statutory or regulatory obligations its architecture is intended to satisfy, and MUST map each to the clauses of this specification relied upon.
Rationale (non-normative)
A structural compliance claim is only useful if it names what it is compliant with. An unmapped claim cannot be examined and should not be credited.
A conforming deployment SHOULD re-verify the acoustic performance required by Chapter 5 and the path enumeration required by ANM-2.2 after any construction, reconfiguration, or hardware change affecting the enclave.